GHS helps organizations across Saudi Arabia achieve and sustain regulatory compliance through rigorous GRC programs — NCA ECC, SAMA CSF, ISO 27001, PDPL, and Aramco CCC/CCC+ — backed by realistic attack simulation and practical, actionable remediation guidance.
Our Experience with Leading Compliance and Cybersecurity Frameworks
About Us
Gray Hat Security (GHS) is a specialist cybersecurity consultancy dedicated to helping organizations understand and reduce real-world risk. Rather than checkbox compliance, we simulate genuine adversary behavior and translate findings into practical, prioritized action — so leadership can make confident, informed decisions.
Empower organizations across the Kingdom to defend their digital landscape with clarity, rigor, and speed.
To be the region's most trusted name in proactive, adversary-informed cybersecurity consulting.
Our Services
Governance, risk, and compliance sit at the center of what we do — reinforced by offensive testing that validates the controls your compliance program depends on.
We help you build — or mature — a governance program aligned to the frameworks that matter in the Kingdom,…
Learn MoreSupplying or contracting with Saudi Aramco means meeting its Third-Party Cybersecurity Standard (SACS-210). We help vendors prepare for and achieve…
Learn MoreWe combine manual, adversary-style techniques with proven tooling to test your external and internal networks, web and mobile applications, APIs,…
Learn MoreWe combine industry-leading scanning tools with manual validation to eliminate false positives, then rank every finding by real business impact…
Learn MoreActive Directory is the backbone of most enterprise networks — and the top target for attackers. We map real privilege-escalation…
Learn MoreBefore you can improve your security posture, you need to know where you stand. We benchmark your core controls —…
Learn MoreFixed-scope Aramco CCC and CCC+ certification support for suppliers across Saudi Arabia. Three ways to get certified, depending on whether your own IT team implements the technical controls, GHS runs the whole programme for you, or you're a small business with under 5 employees. Every package covers the full TPC1.1–1.33 control set and both SACS-210 certification levels.
New to SACS-210? Read our complete Aramco CCC certification guide or, if you are a critical vendor, the CCC+ requirements breakdown.
Package 1
You have an internal IT team. We provide the full documentation set and guide them through implementation.
Your IT team implements, we guide
SAVE 15%Package 2
No internal IT team? We run the entire programme for you, end to end, and keep you certified for two years.
GHS implements everything for you
SAVE 15%Package 3
For companies with fewer than 5 employees. A right-sized documentation set and support scoped to your headcount.
For teams under 5 employees
SAVE 15%Every package covers CCC — base-tier Aramco certification
CCC is the base-tier Cybersecurity Compliance Certificate required of Saudi Aramco suppliers under SACS-210. CCC+ applies to vendors classified as critical — those with deeper access to Aramco systems or data — and adds an on-site audit alongside the document review. Your contract classification determines which one you need.
With IT Support and a team ready to implement, a few weeks is realistic. Without IT Support typically runs longer because GHS deploys all technical controls for you, and CCC+ adds time for audit preparation. The single biggest variable is how much policy and evidence already exists before we start.
Our Saudi National Day offer takes 15% off all packages until 30 September 2026: SAR 7,649.15 for the With IT Support package, where your internal IT team implements the technical controls with our guidance (normally SAR 8,999); SAR 9,349.15 for the Without IT Support package, where GHS runs the entire two-year programme for you (normally SAR 10,999); and SAR 6,550 for the Small Business package, scoped for companies with fewer than 5 employees (normally SAR 7,705.88). Fees for the Aramco-appointed certification body are separate and paid directly by you, as are any software or hardware you choose to buy.
Yes. SACS-210 makes cybersecurity certification a contractual requirement for suppliers, and Aramco verifies status during onboarding and renewal. Suppliers who let certification lapse risk losing eligibility for new work.
SACS-210 is Saudi Aramco's Third Party Cybersecurity Standard — the unified standard that replaced SACS-002. It defines the controls a supplier must implement and evidence in order to earn CCC or CCC+ certification.
Yes. Certification is not one-and-done — it requires ongoing surveillance and periodic renewal. Our Without IT Support package includes two years of continuous evidence and renewal management, plus support through re-audit if needed.
Implementation services only. All packages cover advisory, documentation, remediation guidance and audit support. Software licences, hardware, and Aramco's own certification body fees are not included and are billed directly to you by the respective vendor.
Why Choose GHS
We go beyond automated scans. Our certified consultants think like real attackers, so your organization is prepared for threats that matter — not just checkboxes.
Hands-on experience across NCA ECC, SAMA CSF, ISO 27001, PDPL, and Aramco CCC/CCC+ — we speak the language of Saudi regulators fluently.
A Riyadh-based team of certified GRC and security professionals who understand the local regulatory landscape.
We test the way real adversaries operate, giving your compliance program evidence — not just a checklist.
Every engagement ends with a clear, audit-ready roadmap — not a 200-page PDF nobody reads.
Our Process
We align on objectives, systems in scope, and compliance requirements.
Our team simulates real-world attacks and evaluates controls in depth.
Findings are prioritized by business impact with clear executive summaries.
We help your team fix issues and verify closure with retesting.
Testimonials
"Preparing for our NCA ECC audit felt overwhelming until GHS stepped in. They turned a maze of requirements into a practical roadmap our whole team could actually follow."
"GHS's ability to tailor their engagement to our exact environment was impressive. Their in-depth knowledge and reporting expertise helped us identify and resolve issues before they became real problems."
"GHS found critical vulnerabilities in our e-commerce platform that two previous vendors had missed entirely. Their report was clear enough that our developers had everything patched within a single sprint."
"Our move to the cloud came with risks we didn't fully understand. GHS's cloud security review caught misconfigurations that could have exposed customer data, before they became a real problem."
"The Active Directory assessment was eye-opening — GHS mapped an entire privilege escalation path we had no idea existed. Their hardening recommendations were implemented within weeks."
Insights & Research
July 22, 2026 · 6 min read
July 8, 2026 · 9 min read
July 7, 2026 · 10 min read
Get In Touch
Reach out directly and one of our consultants will get back to you to scope a free initial assessment.